Skip to main content
SSO is available on Enterprise plans. Your domains are enabled by the Blinq team. Talk to your account team to get started.
Blinq supports single sign-on over SAML 2.0. Your identity provider holds your team’s accounts and credentials, and Blinq acts as the service provider. This page covers what happens inside Blinq. It applies the same way whichever identity provider you use.

Before you start

1

Register your domains with Blinq

Email support@blinq.me with the domains you want covered and an example address for each. Blinq adds them for you — there’s no self-serve screen for this. You can register more than one domain, including subdomains, and add or remove them later.
2

Confirm you're the workspace Owner

The SAML settings are reached from the Blinq dashboard under Settings → SAML.
3

Open Blinq and your identity provider side by side

Setup copies values in both directions, so keep both open in separate tabs.
Register your domains first. Until at least one domain is registered, the SAML settings show an upgrade prompt — even on an Enterprise plan. If you’re on Enterprise and being told to upgrade, a missing domain is the reason, not your subscription.

Configuring safely

Stay signed in to Blinq while you configure SSO, and test in a separate browser or a private window. A misconfigured certificate or URL can lock you out of the workspace you’re editing, and only Blinq support can switch enforcement back off.

What enforcement changes

Enforcement is the switch that makes SSO mandatory. It’s checked on Blinq’s side against the email domain someone signs in with. Because enforcement is matched on the email domain, someone who signs in with an address outside your registered domains isn’t routed through SSO at all.

Claiming a card under enforced SSO

Enforcement applies from the very first time someone accesses Blinq, not only on later sign-ins. Claiming a card uses the same sign-in path as everything else, so a new team member on one of your registered domains is sent to your identity provider when they follow their activation link. There’s no separate password or email code step for new joiners to route around.
Allowed email domains and SAML SSO are mutually exclusive. The allowed-domains setting, which limits who can join by invite link, is hidden once SAML SSO is enabled on a workspace.

Starting from your identity provider

By default, people start at Blinq: they enter their email address, and Blinq redirects them to your identity provider to sign in. You can also let people launch Blinq from a tile in their identity provider’s app dashboard. This is an opt-in setting, and Blinq support enables it for your workspace.
Launching from the app tile currently requires enforcement to be switched on as well. With enforcement off, that route returns a server error rather than signing the person in. If you want the app tile without enforcing SSO for everyone, talk to support before rolling it out.

Setup guides

Microsoft Entra ID

Add the Blinq enterprise application and exchange SAML details.

Okta

Create a SAML 2.0 app integration and exchange SAML details.

Google Workspace

Create a custom SAML app and exchange SAML details.

Troubleshooting

Sign-in failures, certificate errors, and people who can’t reach the settings.

Need help?

For any questions or issues, contact Blinq support or email support@blinq.me.